Cavern Manticore: Iranian Hacking Crew Using Cavern Framework
Cavern Manticore is an Iranian hacking crew associated with the Cavern (Cav3rn) framework. The group has been linked to the HOLLOWGRAPH malware,…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
Cavern Manticore is an Iranian hacking crew associated with the Cavern (Cav3rn) framework. The group has been linked to the HOLLOWGRAPH malware,…
Lyceum is a subgroup of the Iranian OilRig group, involved in cyber espionage. Group-IB notes a low-confidence overlap with the HollowGraph campaign.
OilRig is an Iranian state-sponsored cyber espionage group active since 2014, targeting various sectors globally. Lyceum is a subgroup of OilRig.
A suspected China-nexus threat activity cluster, codenamed Operation DragonReturn by Seqrite Labs, has been targeting Indian taxpayers, tax professionals, and corporate finance…
Silver Fox is a Chinese cybercrime group known for targeting organizations in industrial manufacturing and other sectors. They employ sophisticated techniques including…
REF3864 is an intrusion set attributed by Elastic Security Labs for targeting Chinese-speaking regions with malicious installers for Telegram and Opera, delivering…
Conti is a ransomware group that DevMan claimed to have worked with, according to an interview with security researcher Jon DiMaggio. DevMan…
Black Basta is a ransomware group whose internal chats leaked in February 2025, revealing negotiation patterns similar to the Kairos case.
Kairos is a cyber extortion group that operates without encryption, relying solely on data theft and threats of public exposure. It demanded…
Silent Ransom Group, a Conti offshoot, has conducted pure data-theft extortion against U.S. law and finance firms without using encryptors.